Managed XDR

qipf8ff.tmp.qipt — malware analysis report

File info

Filename
qipf8ff.tmp.qipt
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
1.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0366d42d609881b21acc0b2df29fa61f0d61358f
SHA256
de13ceeb09daa34b362013e1fafb650b259318f9e6d65cd32e3902340cdf608b
MD5
7f9e204430fff954a6594077214d662b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process